Storm-1133 is a Gaza-based, Hamas-aligned threat actor publicly named by Microsoft in its Digital Defense Report 2023 (reporting period July 2022 - June 2023). Microsoft observed a wave of 2023 activity in which the group conducted cyber-espionage against Israeli private-sector energy, defense and telecommunications organizations, and also targeted entities linked to Fatah, the rival Palestinian faction dominant in the West Bank. Notable tradecraft included LinkedIn-based social engineering with fake profiles impersonating Israeli HR managers, project coordinators and software developers, delivery of backdoors, and command-and-control infrastructure hosted on Google Drive with a configuration allowing operators to dynamically update C2 to evade static network defenses.
Additional names this actor is known by across other vendors' naming schemes — cross-referenced from external crosswalk sources, not RaqibCTI's own curated aliases (shown at the top of this page). Each source is attributed to its own licence.
Microsoft publicly disclosed Storm-1133 in the Microsoft Digital Defense Report 2023, released in early October 2023, covering activity from July 2022 through June 2023. Microsoft characterized the actor as Gaza-based and assessed that it works to further the interests of Hamas, noting that activity attributed to it has largely affected organizations perceived as hostile to Hamas. Across 2023, Storm-1133 targeted Israeli private-sector energy, defense and telecommunications firms, and separately went after entities loyal to Fatah, the dominant Palestinian faction in the West Bank - an intra-Palestinian espionage dimension consistent with Hamas-Fatah rivalry. The reported TTPs are: (1) social engineering via newly created LinkedIn profiles masquerading as Israeli human-resources managers, project coordinators and software developers to send tailored phishing to targets of interest; (2) attempts to deliver backdoors; and (3) use of C2 infrastructure hosted on Google Drive, with a dynamic-update configuration letting operators stay ahead of static, network-based defenses (a living-off-trusted-cloud-services technique). The group has no confirmed MITRE ATT&CK group ID and no widely adopted third-party aliases at time of writing. Honest limits of public reporting: the body of public reporting is thin and derives almost entirely from a single primary source - Microsoft's Digital Defense Report 2023 - with subsequent press and blog coverage (The Hacker News, SecurityAffairs, Cybernews, CyberMaterial, etc.) essentially re-reporting that one source rather than providing independent corroboration. No independent technical indicators (hashes, domains, named backdoor family) were published, and the 'Storm-' prefix explicitly denotes a Microsoft in-development / uncertain-attribution cluster. Analysts should treat the Hamas attribution and even the group's coherence as provisional. MENA relevance: HIGH and directly on-scope for the Israel country tag - Storm-1133 is a real, primary MENA threat actor whose confirmed 2023 targeting hit Israeli energy, defense and telecom organizations (and intra-Palestinian Fatah-linked entities), though attribution and technical detail are limited to a single Microsoft assessment.